Privacy Policy

Last updated: September 16, 2026

This policy explains what Rifto collects, why, and the choices you have. It also serves as the KVKK aydınlatma metni (information notice) for users in Türkiye.

This page is provided for general information and is not legal advice.

Who we are

Rifto is operated by Konqura Teknoloji A.Ş., registered at Ankara, Türkiye. For privacy questions, contact our data controller at tech@konqura.com.

What we collect

Account data from your Google or Apple sign-in (a user identifier and, where provided, your email and display name).

Media you upload to run a transformation, and the inputs you supply.

Generation and purchase records needed to deliver results and apply credits.

Minimal technical data needed to operate and secure the service.

Why we use it

To create the result you asked for, run your generation, apply and track credits, verify purchases, provide support, and keep the service secure. We do not sell your personal data.

Your media

Media you upload is used only to produce the result you asked for. We do not sell it, and we do not use it for advertising or profiling.

Rifto does not collect, generate, or store face data. We perform no facial recognition, facial detection, face mapping, or face-template extraction, and we do not use your media to identify or verify any individual. Photos and videos you choose to submit may contain faces; we process them only as images and video for the visual transformation you requested, and never as biometric data.

We do not send your name, email address, contacts, or location together with your media. Signed media links are short-lived.

AI processing and third-party providers

To create your result, we upload your submitted media over an encrypted connection to Rifto's servers and then pass it to Eachlabs, the AI platform we use to run transformations. Depending on the trend you choose, Eachlabs routes your media to the model provider that runs that trend — for example OpenAI, Google, Black Forest Labs, Runway or Kling — which produces the result and returns it. Your media is therefore received by Eachlabs and by the model provider for the trend you selected, and by no one else.

Eachlabs processes your media solely to perform the transformation you requested and does not use it to train AI models. Eachlabs keeps a record of each run — the prompt and parameters submitted with it, not the media files — for 180 days. Our agreement with Eachlabs requires it to protect your data to a standard equivalent to this policy.

Model providers process your media under their own published terms, which differ between providers. Eachlabs gives no warranty over how an individual model provider handles data, so we review a provider's data-retention and model-training terms ourselves before we publish a trend that uses it.

We ask for your permission in the app before your media is shared for AI processing. You will see a disclosure naming Eachlabs before your first generation, and you must accept it to continue. If you decline, nothing is uploaded and nothing is shared. You can review this disclosure at any time from Profile → Data & AI Processing.

Retention

The media you upload is stored together with your generation so that you can re-run it, so it is not deleted immediately after your result is produced.

Deleting a project removes it from your library in the app. The media you uploaded is irreversibly deleted from our servers when you delete your account: access is withdrawn immediately, and the stored media is permanently erased after a 30-day grace period.

Finished results held by Eachlabs expire under that provider's retention policy, currently up to 180 days after the result is produced.

Other account data is kept while your account is active, and afterwards only for as long as the law requires us to retain it.

Where your data is stored

The media you upload and your account data are stored with Supabase, our cloud database and storage provider. Access requires an authenticated request tied to your account.

Finished results are held on the infrastructure of our AI processing provider, Eachlabs, and your library links to them rather than to a copy on our own storage.

Your rights

You can delete your account, freeze it, or export your data from within the app or via the Data requests page. Under KVKK and applicable law you may also access, correct, or object to processing — contact tech@konqura.com.

Changes

We may update this policy; material changes will be announced in the app or on this page, with the date above updated.